AWS Application Security Manager, AWS Proactive Security
Manager
Application Security
Aws Cloud Security
Aws Platform
Aws Security
Aws Services
Cloud Platforms
Cloud Security
Cloud Security Assurance
Data Security
Facilities Management
Information Security
InfoSec
Management
Project Management
Risk Governance
Risk Management
Security
Security Compliance
Security Operations
Security Standards
Security Testing
Software Security
Job Description
Amazon’s AWS Proactive Security helps secure AWS launches with structured security reviews, threat modeling, and coordinated penetration testing. In this role, you will lead a team of application security engineers and help raise the application security bar across your area, while owning the security assurance process and using metrics to show measurable risk reduction over time.
What you’ll do
- Lead, grow, and organize a team of application security engineers, including ownership of professional development and coaching through 1:1s, stretch assignments, and hands-on guidance.
- Set strategy for increasing the application security bar and evolve the security assurance process your team operates.
- Own security reviews, threat modeling, and penetration test coordination for your portfolio.
- Define metrics and perform data analysis to measure team performance and security outcomes, focusing on whether the risk is actually being reduced rather than activity counts.
- Review active security reviews and threat models to unblock engineers and weigh in on the highest-risk or most ambiguous findings.
- Drive process and operational improvements that scale review capacity as demand grows.
- Partner with service and business teams to guide penetration test coordination and support remediation of security issues.
- Represent the organization to business leaders and technical staff at all levels, providing clear technical direction and risk-mitigation guidance.
- Manage recruiting, team composition, and hiring bar for your area.
- Contribute to cross-AWS security initiatives and communicate status and results across the organization.
- Participate in complex engineering discussions to ensure proper risk assessment and threat analysis is performed.
Key responsibilities in the day-to-day
You will dig into review throughput, SLA adherence, finding quality, and risk reduced, then decide where to invest next. You will also provide reliable judgment and mature communication while weighing in on critical findings and unblocking engineering teams.
Requirements
- 5+ years of managing and developing teams experience
- 5+ years of progressive work within a software security team or related operating environment
- Bachelor’s degree in Computer Science, Information Security, or a related field
- Knowledge of security of web services, video content protection technologies, cryptography, network security protocols, and operating system security
- Experience applying threat modeling or other risk identification techniques (or equivalent experience)
Preferred qualifications
- CCSP, CEH, CFR, Cloud+, CySA+, GCED, GICSP, or PenTest+
- Master’s degree in Computer Science or a related field
- Knowledge of information security technologies such as security design review, threat modeling, risk analysis, and software testing techniques
- Experience managing remote team members
Benefits
- Sign-on payments
- Restricted stock units (RSUs)
- Health insurance (medical, dental, vision, prescription, Basic Life & AD&D insurance, and an option for Supplemental life plans). EAP, Mental Health Support, Medical Advice Line, Flexible Spending Accounts, and Adoption and Surrogacy Reimbursement coverage
- 401(k) matching
- Paid time off
- Parental leave
About the team
- Diverse Experiences
- Inclusive Team Culture
- Training & Career Growth
- Work/Life Balance
Location: Austin, TX (onsite)
Salary: USD 175,100 - 236,900 per year